Examine the network exhibit: The ACL configuration defined on Core-1 is as follows: If telnet was being used, which device connection would be permitted and functional in both directions? (Choose two.)
E is wrong
Inbound VACL will apply to all ports that are receiving the VLAN traffic. Client 1 may be able to reach client 3 but the traffic will not return since it will be dropped by the VACL.
B is correct because the traffic never crosses the core so the VACL is not used.
D is correct because the server is inbound to VLAN 10 so VACL is not used and return traffic is permitted by VACL.
C is wrong because the return traffic will cross the ACL and is not permitted for client 2.
This picture is in my book and traffic flow is explained.
The only valid solution is B and E because traffic within vlan 20 is not affected from the VACL. Traffic from server 1 will be blocked because of a wrong IP source.
CLIENT1 - CLIENT2 - pass - Forwarded by Access2, no need to go trough CORE1
SERVER1- CLIENT1 - pass - Server 1 inbound VLAN10 on CORE1 return traffic from CLIENT1 in VLAN 20 match the ACL and is permitted.
CL3 - CL2 - drop on forward path by core1 cause match VLAN 20 and CL3 not CL1 as SRC IP
CL1 - CL2 - pass - no ACL cause forwarded by Access2
SR2 - CL2 - pass on forward path by core1 cause match VLAN 10
Drop on return path by core1 cause match VLAN 20 and no CL1 as SRC IP
SR1 - CL1 - pass on forward path by core1 cause match VLAN 10
pass on return path by core1 cause match VLAN 20 and CL1 as SRC IP
CL1 - CL3 - pass on forward path by core1 cause match VLAN 20 and CL1 as SRC IP
drop on return path by core1 cause match VLAN 20 and not CL1 but CL3 as SRC IP
D - because initial traffic (inbound vlan 10) is not matched on VACL to the client, but return traffic (inbound vlan 20) is matched and permitted by ACL.
what you seem to be forgetting here is the VACL will only apply on core 1 for traffic that is coming into the switch and into VLAN 20, so any device outside VLAN 20 will not have the source IP of the client. Hence B and E are correct.
B & E is correct. ACL permits traffic only from 10.101.20.21/32 IP address that is Client1.
The question asks for a connection "in both directions". So only devices in the same VLAN can communicate in both directions, as they are not affected by a VACL.
This section is not available anymore. Please use the main Exam Page.HPE6-A73 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
pabx31
Highly Voted 3 years, 6 months agosentinel44
Highly Voted 3 years, 3 months agojohnhenri
Most Recent 1 year agoudo2020
1 year, 7 months agodemanmetdehamer
6 months agoOscarChew
1 year, 8 months agoSeidorBruno
1 year, 9 months agopoy4242
3 years agoMar_a_Lagoon
3 years, 5 months agoDisposable_Me_2018
3 years, 6 months agogondolf
3 years agokup
3 years, 7 months agoI_C_U
3 years, 7 months agoclupato2
3 years, 8 months agoseb6869
3 years, 8 months agoAM1234
3 years, 10 months agoWilliams926
3 years, 10 months agopublic2002
3 years, 11 months agopublic2002
3 years, 11 months ago